Перейти к содержимому
Noroxi

Записи SonicWall

236 опубликованных записей вендора sonicwall.

Профиль для исследователя

Попали в KEV
23 · 9,7 %
С эксплойтом
36 · 15,3 %
Pre-auth RCE
22
С записью об исправлении
5,5 %
Медиана: публикация → KEV
197 дн.

Все записи

236 записей
  • CVE-2021-44228
    100Срочно

    Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %

    apache · log4j10 дек. 2021 г.

  • CVE-2021-20038
    99Срочно

    A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthentic

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    sonicwall · sma 200 firmware8 дек. 2021 г.

  • CVE-2024-53704
    98Срочно

    An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 95 %

    sonicwall · sonicos9 янв. 2025 г.

  • CVE-2021-45046
    96Срочно

    Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack

    КритическаяCVSS 9,0KEVГотовый эксплойтEPSS 100 %

    apache · log4j14 дек. 2021 г.

  • CVE-2024-38475
    96Срочно

    Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.

    КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 100 %

    apache · http server1 июл. 2024 г.

  • CVE-2021-20021
    96Срочно

    A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 89 %

    sonicwall · email security9 апр. 2021 г.

  • CVE-2019-7481
    90Срочно

    Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources.

    ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %

    sonicwall · sma 100 firmware17 дек. 2019 г.

  • CVE-2022-0847
    89Срочно

    A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 93 %

    linux · linux kernel10 мар. 2022 г.

  • CVE-2023-44221
    81Срочно

    Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administr

    ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 76 %

    sonicwall · sma 200 firmware5 дек. 2023 г.

  • CVE-2021-20016
    81Срочно

    A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 40 %

    sonicwall · sma 100 firmware4 февр. 2021 г.

  • CVE-2021-20028
    78На этой неделе

    Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, s

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 30 %

    sonicwall · sma 210 firmware4 авг. 2021 г.

  • CVE-2020-5135
    77На этой неделе

    A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 27 %

    sonicwall · sonicos12 окт. 2020 г.

  • CVE-2025-23006
    76На этой неделе

    Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 23 %

    sonicwall · sma8200v23 янв. 2025 г.

  • CVE-2024-40766
    75На этой неделе

    An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 18 %

    sonicwall · sonicos23 авг. 2024 г.

  • CVE-2026-83548
    73На этой неделе

    A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path.

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 9 %

    sonicwall · sma8200v1 сент. 2026 г.

  • CVE-2026-15409
    72На этой неделе

    A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface.

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 7 %

    sonicwall · sma6210 firmware14 июл. 2026 г.

  • CVE-2013-1359
    66На этой неделе

    An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Un

    КритическаяCVSS 9,8Готовый эксплойтEPSS 89 %

    sonicwall · analyzer11 февр. 2020 г.

  • CVE-2021-20023
    64На этой неделе

    SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on th

    СредняяCVSS 4,9KEVГотовый эксплойтEPSS 51 %

    sonicwall · email security20 апр. 2021 г.

  • CVE-2026-83549
    64На этой неделе

    Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identi

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 11 %

    sonicwall · sma8200v1 сент. 2026 г.

  • CVE-2021-20022
    63На этой неделе

    SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to

    ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 17 %

    sonicwall · email security9 апр. 2021 г.

  • CVE-2024-6387
    62На этой неделе

    Openssh: regresshion - race condition in ssh allows rce/dos

    ВысокаяCVSS 8,1Proof of conceptEPSS 100 %

    sonicwall · sma 6200 firmware1 июл. 2024 г.

  • CVE-2022-22274
    62На этой неделе

    A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Serv

    КритическаяCVSS 9,8Proof of conceptEPSS 76 %

    sonicwall · sonicos25 мар. 2022 г.

  • CVE-2019-12255
    62На этой неделе

    Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4).

    КритическаяCVSS 9,8Proof of conceptEPSS 75 %

    windriver · vxworks9 авг. 2019 г.

  • CVE-2026-15410
    62На этой неделе

    Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Man

    ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 12 %

    sonicwall · sma6210 firmware14 июл. 2026 г.

  • CVE-2023-34127
    61На этой неделе

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GMS, SonicWall Analyti

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 86 %

    sonicwall · analytics12 июл. 2023 г.